This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phreedom-12.1-squeeze-i386-openstack.tar.gz.sig gpg: Signature made Tue Jun 4 23:25:57 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 541eeaf919a3aa6eb314fce053fa9b1945d5fda4 * md5sum b3f7e12a2ae741cc3fc154435e7546e2 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnd7AAoJEIXCXpWhbrlNjL0IAK6c7dbI3Pu1sQOozGZxeWom ZYNkDLMB6t4LQf9MZj4RgC8ZfW41XqYB7wixGXnpxT2Jhmywt6eAEFo1Ye8t1m2z SANe3DQnE/PyvJPeMv0wTe0o9Sf8V4vfl0VBplIfagTf4LYwUNtixMvDOXGJ+b7k c4jQH1yJZFTJrER9r2PyltpjoOENcoqo/4CURQfqBiMpl0qq2XtiO2JVLQS4/iFe b7nPpW9K8x8uVB6MpyqjaN6DFIkViAStjTRKRCBso5A0UQUFQ/xwWcnBtI5tGERX AsrIT30gme8ZS6Z2U9Owd36n9SBeNsUhoN2SkTHpV6xtmyOai+RChGuUDb0SU0Y= =r1y4 -----END PGP SIGNATURE-----